Ransomware victim disclosure
← All victimsHouston Community College
listed as hccs.edu · Claimed by Shinyhunters · listed 6 hours ago
Status timeline
- ListedJun 15, 2026
- Data leakeddate unknown
At a glance
- Group
- Shinyhunters
- Status
- Data leaked
- Country
- United States
- Sector
- Education
- Listed on leak site
- Jun 15, 2026
About the victim
AI dossier — public-source company profileHouston Community College (HCC) is a multi-campus community college system serving the Houston area with 19 campuses. It offers over 85 programs including university transfer degrees, workforce training, apprenticeships, adult education, and high school completion programs. The institution serves tens of thousands of students annually with flexible learning options including online, hybrid, and in-person classes.
- Industry
- Higher Education - Community College
- Address
- Multiple campuses across Houston, Texas (19 locations)
Attack summary
Severity: critical — Confirmed exfiltration at massive scale of highly sensitive regulated data: 344,000+ international student documents including passports and immigration records; 12,000+ financial aid records with PII (names, SSN-related FAFSA data, birthdates); 14,000+ health/immunization records; and hundreds of thousands of student PII records. This includes multiple categories of regulated data (SEVIS immigration records, FERPA-protected education records, health information) affecting a large institution.ShinyHunters claims to have exfiltrated comprehensive student records and institutional data across all HCC campuses. The group states they obtained hundreds of thousands of student records, over 344,000 international student documents including SEVIS forms and visa materials, financial aid records, health/immunization data, and library credentials. A final ransom deadline of 18 June 2026 was issued with threat of public leak.
Data the group says was taken
AI dossier — extracted from the leak post- Student personal records (name, address, phone, email, DOB, gender, ethnicity)
- Academic data (enrollment status, GPA, major, student ID, class rosters, grades)
- International student documents (SEVIS I-20 forms, visa applications, passports, bank statements, tax returns, immigration affidavits)
- Financial aid records (FAFSA/ISIR data, bursar reports with 12,000+ records)
- Health/immunization records (14,000+ vaccination records, meningitis compliance documentation, 15,000+ additional health documents)
- Library credentials and PINs
- Student email accounts (@student.hccs.edu)
What the group claims
Hundreds of thousands of student records containing full name, home address, phone, email, date of birth, gender, ethnicity, enrollment status, GPA, major, and student ID across all campuses. Daily and full student roster exports library credentials, PINs, and @student[.hccs[.edu accounts. Over 12,000 financial aid and bursar reports including FAFSA/ISIR suspense data with names, birthdates, emails, phones, and home addresses. Class rosters with birthdates, grades, academic programs, and contact information for tens of thousands of enrolled students per term. Over 344,000 international student documents including SEVIS I-20 forms, visa applications, passports, bank statements, tax returns, immigration affidavits, and acceptance letters. Over 14,000 student immunization and vaccination records including meningitis compliance documentation. Over 15,000 additional health and immunization documents across report archives and A LOT more was compromised. This is a final warning to reach out by 18 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 16 June 2026 | Warning: FINAL WARNING PAY OR LEAK
Sources
- Victim sitehccs.edu
Source
Indexed 6 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

